← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 18, 2026 · 20:17via CVEFeed

CVE-2026-93838 - SGLang through 0.5.20 Unbounded Memory Allocation via STAGING_REQ chunk_idx

Brief

CVE ID : CVE-2026-93838

Published : Sept. 18, 2026, 8:17 p. m.

  • 38 minutes ago

Description : SGLang versions through 0.

  • 20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments.

Attackers with access to the decode engine's internal ZMQ rank port can send a frame with an extremely large chunk_idx value, causing the scheduler to allocate memory until the system runs out and terminates the process.

Severity: 8.2

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed→